CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-65474
9.8 CRITICAL

An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via renaming a PHP …

Dec 11, 2025
CVE-2025-65473
9.1 CRITICAL

An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with Administrator privileges to execute arbitrary code via …

Dec 11, 2025
CVE-2025-14265
9.1 CRITICAL

In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or …

Dec 11, 2025
CVE-2025-13764
9.8 CRITICAL

The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16. This is due to the 'WP_CarDealer_User::process_register' …

Dec 11, 2025
CVE-2025-67511
9.6 CRITICAL

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Injection …

Dec 11, 2025
CVE-2025-67510
9.4 CRITICAL

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller …

Dec 10, 2025
CVE-2025-65294
9.8 CRITICAL

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command …

Dec 10, 2025
CVE-2025-65830
9.1 CRITICAL

Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adversary located "upstream" can decrypt …

Dec 10, 2025
CVE-2025-65827
9.1 CRITICAL

The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an …

Dec 10, 2025
CVE-2025-65826
9.8 CRITICAL

The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retrieved this, and found the physical …

Dec 10, 2025
CVE-2025-65823
9.8 CRITICAL

The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an …

Dec 10, 2025
CVE-2025-65820
9.8 CRITICAL

An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mobile application which opens a hidden page. …

Dec 10, 2025
CVE-2023-53740
9.8 CRITICAL

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit …

Dec 10, 2025
CVE-2020-36902
9.8 CRITICAL

UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send …

Dec 10, 2025
CVE-2020-36898
9.1 CRITICAL

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers to delete files without authentication. …

Dec 10, 2025
CVE-2020-36897
9.8 CRITICAL

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to upload malicious ASPX scripts. …

Dec 10, 2025
CVE-2020-36892
9.8 CRITICAL

Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modify user roles. Attackers can …

Dec 10, 2025
CVE-2020-36885
9.8 CRITICAL

Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allows remote attackers to execute arbitrary code. Attackers can …

Dec 10, 2025
CVE-2025-65602
9.8 CRITICAL

A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.

Dec 10, 2025
CVE-2025-64539
9.3 CRITICAL

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker …

Dec 10, 2025
CVE-2025-64538
9.3 CRITICAL

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker …

Dec 10, 2025
CVE-2025-64537
9.3 CRITICAL

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker …

Dec 10, 2025
CVE-2025-13607
9.4 CRITICAL

A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

Dec 10, 2025
CVE-2025-65792
9.1 CRITICAL

DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.

Dec 10, 2025
CVE-2025-34394
9.8 CRITICAL

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserialization …

Dec 10, 2025
CVE-2025-34393
9.8 CRITICAL

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, …

Dec 10, 2025
CVE-2025-34392
9.8 CRITICAL

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that …

Dec 10, 2025
CVE-2025-13184
9.8 CRITICAL

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions …

Dec 10, 2025
CVE-2025-41732
9.8 CRITICAL

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full …

Dec 10, 2025
CVE-2025-41730
9.8 CRITICAL

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full …

Dec 10, 2025
CVE-2025-13613
9.8 CRITICAL

The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This is due to the plugin …

Dec 10, 2025
CVE-2025-67506
9.8 CRITICAL

PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/record/buffer/convert through missing authentication. The …

Dec 10, 2025
CVE-2025-61811
9.1 CRITICAL

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2025
CVE-2025-61809
9.1 CRITICAL

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker …

Dec 10, 2025
CVE-2025-61808
9.1 CRITICAL

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code …

Dec 10, 2025
CVE-2025-67494
9.3 CRITICAL

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats …

Dec 9, 2025
CVE-2025-66039
9.8 CRITICAL

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set …

Dec 9, 2025
CVE-2025-67489
9.8 CRITICAL

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution on the development server through …

Dec 9, 2025
CVE-2023-53774
9.8 CRITICAL

MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to send commands to manipulate TV systems. Attackers can …

Dec 9, 2025
CVE-2023-53771
9.8 CRITICAL

MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Attackers can send crafted POST requests to …

Dec 9, 2025
CVE-2021-47731
9.8 CRITICAL

Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocumented page. Attackers can exploit the hidden …

Dec 9, 2025
CVE-2021-47728
9.8 CRITICAL

Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit …

Dec 9, 2025
CVE-2025-66456
9.8 CRITICAL

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in …

Dec 9, 2025
CVE-2025-65741
9.8 CRITICAL

Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution …

Dec 9, 2025
CVE-2025-64113
9.8 CRITICAL

Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby …

Dec 9, 2025
CVE-2025-65882
9.8 CRITICAL

An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ipad_opad allowing attackers to potentially write arbitrary files or execute arbitrary commands.

Dec 9, 2025
CVE-2025-59719
9.8 CRITICAL

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to …

Dec 9, 2025
CVE-2025-59718
9.8 CRITICAL KEV

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, …

Dec 9, 2025
CVE-2025-63742
9.8 CRITICAL

SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database …

Dec 9, 2025
CVE-2025-67504
9.1 CRITICAL

WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, …

Dec 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.